Threat Level: green Handler on Duty: Brad Duncan

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Last-Modified
CF-RAY
Cf-Request-Id
CF-Cache-Status
Accept-Ranges
Link
Pragma
ETag
Expect-CT
X-Powered-By
X-XSS-Protection
Via
Age
X-Cache
Content-Security-Policy
Access-Control-Allow-Origin
Content-Language
Referrer-Policy
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-UA-Compatible
Alt-Svc
P3P
X-Served-By
X-Xss-Protection
X-Timer
X-Download-Options
Access-Control-Allow-Headers
X-Varnish
Access-Control-Allow-Methods
Access-Control-Allow-Credentials
X-Request-Id
X-AspNet-Version
X-Adblock-Key
X-Runtime
X-Request-ID
X-Permitted-Cross-Domain-Policies
Content-Security-Policy-Report-Only
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
P3p
X-DNS-Prefetch-Control
X-Cacheable
Timing-Allow-Origin
X-FRAME-OPTIONS
X-Content-Security-Policy
X-Iinfo
Status
Content-Encoding
Feature-Policy
X-AspNetMvc-Version
X-CDN
X-Envoy-Upstream-Service-Time
Upgrade
Access-Control-Expose-Headers
X-Drupal-Dynamic-Cache
Access-Control-Max-Age
X-Via
Keep-Alive
X-Dns-Prefetch-Control
Request-Context
X-Ws-Request-Id
Server-Timing
X-Robots-Tag
X-AH-Environment
X-Ua-Compatible
X-Server
X-Hacker
X-Age
X-Turbo-Charged-By
X-Server-Powered-By
X-Proxy-Cache
X-Cache-Group
X-Backend
Host-Header
X-Nginx-Cache-Status
EagleId
X-Amz-Request-Id
X-Amz-Id-2
Report-To
X-LiteSpeed-Cache
X-Rq
X-Varnish-Cache
X-Page-Speed
Grace
X-UA-Device
X-Swift-CacheTime
X-Swift-SaveTime
X-Pingback
Ali-Swift-Global-Savetime
X-Device
EagleEye-TraceId
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
Cf-Railgun
X-Vhost
X-Amz-Version-Id
NEL
X-Host
X-Dispatcher
X-OneAgent-JS-Injection
X-Server-Id
X-CST
X-Node
Allow
Surrogate-Control
X-Cache-Spec
Request-Id
X-Backend-Server
X-EdgeConnect-Origin-MEX-Latency
X-EdgeConnect-MidMile-RTT
X-WebKit-CSP
X-Readtime
X-Response-Time
Accept-CH
X-Akam-SW-Version
X-Webkit-CSP
Xkey
X-HW
Accept-Ch-Lifetime
X-Country
X-Ac
X-Application-Context
Content-Location
X-Language
X-Ruxit-JS-Agent
MS-Author-Via
Rating
X-Template
X-Cloud-Trace-Context
X-Cache-Lookup
X-Url
X-Mod-Pagespeed
X-B3-TraceId
Edge-Control
X-Vname
X-TtlSet
X-PC
X-Clacks-Overhead
X-ESI
X-MS-InvokeApp
X-Trace
X-Varnish-TTL
X-GitHub-Request-Id
X-Content-Type
Fastly-Restarts
X-ASPNET-VERSION
X-Origin-Cache
X-Cnection
X-Rack-Cache
X-FastCGI-Cache
X-D2id
X-Kinja-Server
X-Kinja-Revision
X-Kinja
X-Exp-Variant
X-Use-Magma
X-GoogleNews-Bot
X-Exp-Id
X-Kinja-Build
X-Cdn-Fetch
X-Country-Code
Accept-Ch
X-VARITI-CCR
Arr-Disable-Session-Affinity
Verso
X-Goog-Hash
Accept-CH-Lifetime
X-Server-Name
X-Vcap-Request-Id
X-Cached
X-Navigation-Version
Cache-Tag
X-Client-IP
X-Buckets
X-Abt-Application-Version
X-Amz-Rid
X-Powered-By-Plesk
X-ORACLE-DMS-ECID
Service-Worker-Allowed
X-Ttl
RTSS
X-Fastly-Request-ID
X-Cache-TTL
X-Middleton-Response
X-Sol
Response
Pagespeed
Display
X-Middleton-Display
Access-Control-Request-Method
X-MSEdge-Ref
X-Element-Page-Cache
X-Powered-CMS
X-NF-Request-ID
Public-Key-Pins
X-Dw-Request-Base-Id
X-Upstream
X-Server-ID
X-Version
X-SRCache-Store-Status
X-SRCache-Fetch-Status
X-Edge
X-Px
S
X-Kinsta-Cache
X-Edge-Location-Klb
X-LLID
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
Realpath
X-Oneagent-Js-Injection
X-Accel-Expires
SPRequestDuration
SPIisLatency
SPRequestGuid
X-SharePointHealthScore
X-Jurisdiction
X-HP-Webp
X-T
X-Mid
X-MCACHE
X-ECACHE
X-PressLabs-Stats
X-TTL
X-Forwarded-Proto
X-Content-Security-Policy-Report-Only
X-Instrumentation
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Kraken-Routeconfig-Destination
X-Shield-Request-Id
X-DynaTrace
X-Correlation-Id
X-Ruxit-Js-Agent
Edge-Cache-Tag
Charset
Pinterest-Version
Pinterest-Generated-By
X-Recruiting
X-Pinterest-Rid
X-Cache-Key
Fastcgi-Cache
TP-L2-Cache
TP-Cache
X-Amz-Server-Side-Encryption
X-Mg-S
X-Content-Digest
X-Ezoic-Cdn
X-Release
Filters
X-ORACLE-DMS-RID
Nginx-Cache
X-Id
X-Request-Processing-Time
X-Request-Received
TCN
Server-Node
X-Logged-In
Front-End-Https
Alternate-Protocol
Cache-Tags
X-XRDS-Location
X-Forwarded-For
Content-MD5
X-Litespeed-Cache
X-Origin-Upstream-Status
Fusion-Content-Id
Fusion-Component-Id
Fusion-Content-Source
Fusion-Deployment-Id
Fusion-Template-Id
Fusion-Source
X-Amzn-Trace-Id
Server-Name
X-Geo-Country
X-Origin-Server
X-Grace
X-Hostname
X-Amz-Replication-Status
X-F-Cache
X-Protected-By
X-Rid
Cleartype
X-AppVersion
X-Contextid
X-Az
Host
X-RateLimit-Remaining
X-Activity-Id
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-WebKit-CSP-Report-Only
X-GUploader-UploadID
X-Goog-Storage-Class
X-Goog-Metageneration
X-Goog-Generation
X-HS-Hub-Id
X-HS-Cache-Config
X-Www-Served-By
X-HS-Content-Id
X-HS-Combine-CSS
X-Frontend
X-LB-Cache
X-Debug-Info
Section-Io-Cache
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
MicrosoftSharePointTeamServices
X-Browser-Type
X-NWS-LOG-UUID
X-Git-Hash
X-Ser
X-Page-Id
X-Aspnetmvc-Version
X-Tec-Api-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Cache-Age
X-Respond-Thread
AR-Request-ID
AR-ATIME
X-VCache
Accept-Charset
X-Source
Ar-Sid
AR-CACHE
AR-PoweredBy
X-Content-Options
X-Varnish-Age
X-Upgrade-Enabled
X-DIS-Request-ID
X-Hits
X-Mobile-URL
Paypal-Debug-Id
X-Daa-Tunnel
ServerID
X-Varnish-Backend
Access-Control-Allow-Method
X-Varnish-Grace
X-Signature
X-B-Cache
X-CACHE-GROUP
Viewport
X-Cache-Action
X-Is-Crawler
X-Aspnet-Duration-Ms
Healthy
X-Flags
X-FB-Debug
X-Request-Guid
X-Route-Name
X-Providence-Cookie
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-B3-Sampled
Payment
X-Whom
X-XRDS-LOCATION
X-AOL-HN
X-TT
X-App-Environment
Node
Version
X-N
X-Type
X-Microsite
X-Seen-By
X-Request-Handler-Origin-Region
DynaTrace
X-Mobile
Fastcgi-Useragent
X-Load-Cache
DC
X-Fastcgi-Cache
MS-CV
X-Yandex-Sdch-Disable
X-Ab
X-HTML-Minification-Powered-By
X-Cache-Expired-At
X-Distributor
SRV
Retry-After
X-Cache-Control
Filterid
X-Tt-Trace-Host
X-IPLB-Instance
X-Tt-Trace-Tag
Frame-Options
X-User-Agent
X-Original-Request-Id
X-Response-Served-From
X-Real-IP
X-Instance
X-Ua-Device
X-RemovedCookies
X-ProcessESI
X-Tumblr-Pixel-0
X-Tumblr-User
X-Tumblr-Pixel-1
X-Varnish-Server
X-Tumblr-Pixel
X-UUID
X-IPS-LoggedIn
X-Jobs
X-Content-Powered-By
Access-Control-Request-Headers
X-Proxy
Ms-Operation-Id
X-Region
X-RTag
X-Cluster-Name
X-Debug-IsConnected
Uber-Trace-Id
X-Proxy-Cache-Status
X-Page-View
X-Debug-IsPreview
VIX-Pulpo-Node
VIX-Pulpo-Upstream-Status
Refresh
X-Cacheable-TTL
X-Adobe-Content
X-Cache-Time
X-Adobe-Loc
X-Framework
X-Device-Type
NGB
X-B
X-FireWall-Port
X-Accel-Buffering
X-G
X-Debug
Cache
X-Zen-Fury
X-FW-Dynamic
X-FW-Server
X-FW-Static
X-FW-Type
X-FW-Hash
X-FW-Serve
X-Vgn-Hpd-Reason
Countrycode
X-Wix-Request-Id
Section-Io-Origin-Time-Seconds
Section-Io-Origin-Status
Section-Origin-Responded
Section-Io-Id
X-RateLimit-Limit
X-Mg-Request-UUID
X-Oracle-Dms-Rid
X-Nginx-Cache
Cache-Status
X-Azure-Ref
X-Time
X-App-Version
X-CDN-Forward
Surrogate-Key
X-NGENIX-Cache
X-Is-Bot
X-Rendered-As
Country
X-Drupal-Cache-Tags
X-Cache-Rule
X-Ms-Version
S-Cnection
X-Cache-Hit
X-Node-Name
X-EdgeConnect-Cache-Status
X-Ms-Request-Id
X-App-Server
SD-X-WS
Eomportal-Instance
Referer-Policy
Amp-Access-Control-Allow-Source-Origin
X-TA-CDN-Provider
X-Environment-Context
Liferay-Portal
X-L-Path
X-Cache-Operation
X-SaId
Selected-Fe
X-Varnishpool
Meta-Geo
From-Origin
X-Proxy-Build
X-RN-RSRV
X-Timing-Wait
X-JoinUs
X-Yottaa-Metrics
X-Yottaa-Optimizations
X-Tumblr-Pixel-2
X-ES-SERVER
X-UPSTREAM-Address
X-TNCMS
X-Loop
ServedBy
X-Drupal-Cache-Contexts
X-PHP-Backend
CF-IPCountry
X-Cache-Server
X-Pubstack
X-Varnish-Beresp-Grace
X-Varnish-Hostname
X-Backend-Host
X-Request-Time
X-Handled-By
X-GG-Cache-Date
X-Shopify-Stage
X-ShopId
X-Cache-TTL-Remaining
Azure-Version
Cache-Name
Azure-SlotName
Azure-SiteName
Azure-RegionName
X-Sorting-Hat-PodId
X-S-Maxage
X-ShardId
X-Server-W
Property-Id
Fastly-SSL
Protected
Webcakes-Region
X-No-Session
X-NYM-Debug-Backend
X-Proto
Azure-InstanceId
X-Sorting-Hat-ShopId
X-Alternate-Cache-Key
X-Be
X-Human
X-Storefront-Renderer-Rendered
Webcakes-App-Version
X-Origin-Hint
X-Via-Fastly
TWC-GeoIP-Country
TWC-Device-Class
X-R9-Blue-Green-Version
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Connection-Speed
Webcakes-App-Name
TWC-Privacy
X-Format
X-Hl-Ver
X-LJ-Flow-ID
X-Origin-Date
X-OCL
X-PCL
X-LAGOON
X-ProxyCache-Key
X-Access
Decoy-Debug-Status
X-ProxyCache-Status
Decoy-Debug-TTL
X-RCS-CacheZone
Decoy-Debug-Key
X-Adobe-Source
Country-Code
X-BYPASS-REASON
X-Backend-Name
X-AWS-Id
Cache-Tv-Group
X-Say-TTL
X-Say-Cacheable
X-VWS-Id
X-SayCDN-TTL
X-Section
Nel
Akamai-GRN
X-Endurance-Cache-Level
X-FB-TRIP-ID
X-Sql-Count
X-Xfnlog-Site
X-PERF
X-Status
Apigw-Requestid
X-Akamai-Edgescape
X-UA-Device-Type
X-ApacheServer
X-Sql-Duration-Ms
X-Revision
Mn-Server-Ip
X-Labrador-Cache-Channel
X-Cache-PHP
X-PHP-Host
X-Hyper-Cache
X-Hosted-By
X-Uri
X-Rule
X-Redis-Cache
X-Cache-Type
X-Web-Node
Xserver
X-MP-GENERATED-AT
X-ATG-Version
AMP-Access-Control-Allow-Source-Origin
X-FW-Version
X-Aws-Lambda-Call-Status
X-B3-SpanId
X-Trace-Id
X-ServerID
X-WA-Info
X-Content-Age
X-Tumblr-Pixel-3
X-Time-Microsecs
X-Parallel-Accel
X-Dc
X-Soup
X-Cached-By
Backend
X-Cache-Enabled
X-CSRF-Token
X-Akamai-Transformed
GEO-INFO
X-TT-LOGID
OT-Force-Account-Verify
Count-Hit
X-Mode
X-Datadome
X-Detected-As
X-Cluster-Node
X-Azure-Ref-OriginShield
X-Edge-Location
X-Varnish-Cache-Hits
X-Microcachable
X-Info
X-Bc-Bl
X-Varnish-Beresp-Status
X-APP-VERSION
Web-Mar-Node
X-Generation-Time
X-CS
X-Cache-Host
Cross-Origin-Opener-Policy
X-Varnish-Hits
X-Servername
X-Cache-NGX
X-Debug-Cache
X-Amzn-Remapped-Content-Length
X-Amzn-RequestId
X-Amz-Apigw-Id
X-Routing-Service
X-Zipkin-Id
X-Storage
X-Proxied
X-Platform
DataCenter
Who
X-HP-Trace-Id
X-B3-Traceid
X-Extlb
X-Unique-ID
X-Varnish-Beresp-Ttl
X-Origin-CC
X-DataDome
X-Origin-TTL
X-SRV
DCR-Processing-Time-Ms
DCR-Decision-By
Fastcgi-X-Cache-Version
X-NAPM-TraceId
X-Connection-Hash
Expiry
X-Magnolia-Registration
Fastly-Backend-Name
X-CF-Lambda-Fn
X-CF-Lambda-Version
Host-ID
X-Request-URI
Apple-News-Services-Handled
X-Processor
X-PBS-Appsvrname
X-Air-Trace-Id
X-Air-Source
X-Air-Hostname
X-PAYTM-SRV-ID
X-D
X-Locale
X-Epic-Correlation-Id
BehaviorPad-Version
X-Generated-On
X-Geo-Header
Cache-Host
X-External-Request-Id
X-From
Apple-News-Services-Host
A
Apple-News-Services-Parsed-Url
Apple-News-Services-Request-Url
CDCHOST
CDN-Cache
CDN-Uid
X-Developer
X-Destination
X-Rewrite-Enabled
CDN-RequestId
CDN-RequestCountryCode
CDN-CachedAt
CDN-EdgeStorageId
CDN-PullZone
X-Level-Front-Cache
X-Location
X-Cache-NE
Mobile-Detection-Method
X-Vtex-Remote-Cache
X-Application
X-Aicache-OS
Odigeo-Trace-Id
X-Vtex-Processado-Em
X-VG-WebServer
Meta-Geo-Continent
X-Vdms-Path
X-ARC
X-VG-WebCache
X-Aed
X-A-Wwc
X-A-Ccd
Req-Svc-Chain
X-A
Surrogated-Key
T-Server
SID
Server-Info
X-A-Dgt
X-A-Dcw
X-A-Dam
Rendered-Blocks
X-B-Cookie
X-Vdms-Version
X-Service
M-TraceId
X-Bip
X-Cache-Bucket
X-ScT
X-Rojux
X-S
X-S-Cookie
X-SRCache-Key
X-Session-Fingerprint
MD5-Digest
X-BCube-Filmed-By
X-Thanos
Upgrade-Insecure-Requests
S-Rt
Gh-Request-Id
Esi-Enabled
X-Clientip
L
State
X-Core-Value
Content-Disposition
Kp-EeAlive
Fastly-Drupal-HTML
Origin
Memcached
Location
Fastcgi-Cache-TTL
Pagetype
X-Backend-State
CacheControlHeader
X-Developers
PFcat
X-Cms-Context
X-HN
X-VarnishDD-TTL
Source
X-Request-UUID
X-Ua
X-JWT-State
X-Varnish-Ttl
AKAMAI
X-Sucuri-ID
X-EC-Lua
Path
X-Via-JSL
X-Ratelimit-Reset
X-NWS-UUID-VERIFY
X-Is-Gdpr
X-Rocket-Build-Number
X-Cache-Grace
UCS
X-Sigma
X-Gamma-Serve
X-Sigma-Backend
X-TrackingId
X-Var-Ttl
X-Served-From
X-Has-Esi
X-VHOST
X-Hash
X-Scheme
User-Cache-Control
X-AIR-PT
Cross-Origin-Window-Policy
X-Tb
Url
C-Via
X-Varnish-Url
X-VG-TLSProxy
X-VC-Cache
DSUID
Thinkindot-Control
Wxu-Next-Commit
Wxu-Next-Hostname
Wxu-Next-Region
X-Orig-Expires
X-Shop-Environment
X-Tenant
Vix-Hermes-Req-Id
X-Forwarded-Path
X-Thinkindot-L3
X-Accel-Expires-Debug
Thinkindot-CacheControl
Thinkindot-CacheControl-Type
X-Device-Os
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
TDXMobile
X-Rebelmouse-Surrogate-Control
X-Loc
X-LI-UUID
X-Date
X-Men
X-Micro-Cache
X-Csrf-Jwt
X-Li-Pop
X-Li-Fabric
X-Forwarded-Site
X-Fastly-Backend
X-Eu-Site
X-Generated-In
X-Envoy-Decorator-Operation
X-GoCache-CacheStatus
X-Minions-Version
X-NU-AKA-ACS-Version
X-Cache-Tags
X-Rebelmouse-Cache-Control
X-Request-Host
X-Cache-Info
X-Branch-Name
X-Cache-Debug
X-CGP
X-Proxy-Upstream
X-Origin-Expires
X-Origin
X-Owner
X-Platform-Server
X-Cluster
X-Policy
X-Site-Version
X-Generated-By
Ha-Gx-Prefs
Fastly-SWR
Fastly-SIE
HA-Ipaddr
L5d-Success-Class
PB-RID
PB-PID
Content-Secure-Policy
NtCoent-Length
X-Forwarded-Host
X-Amz-Meta-S3cmd-Attrs
Arc-Country
Cf-Device-Type
Cmstype
Cmsid
Pics-Label
Arc-Version
Server-Host
Svr
X-Ratelimit-Limit
X-Srv
V-Age
Release
Platform
X-Wikidot-Static-Cache
X-Wikidot-Backend
Server-Ext
X-DPWN-IS-SECURE
Server-Hostname
Sever-Int
Cache-Key
Adler-Geo
X-Fmm-Version
X-FC-Vary-Parameters
X-Fastly-Cache
X-WADP-Cache
X-Viewer-Country
X-RateLimit-Remaining-Second
X-Mvc-Supplant-Cachable
X-RateLimit-Limit-Second
X-Old-Content-Length
X-PF-Uncompressing
X-Qloud-Router
X-Req
X-SIPLIST1
X-Hnp-Log
X-Goog-Meta-Goog-Reserved-File-Mtime
True-Client-Country-4JS
X-Irp-Debug
X-Slack-Backend
X-Variation
X-Gen-Mode
NGX
Ec-Rule-Version
X-GeoIP-City
NM-Fastcgi-Cache
We-Hiring
IsBot
X-Clara-WADP
X-Fetched-On
X-VServer
X-Nginx-Cache-Key
Mail-Subject
Is-Eu
X-Block-Status
X-GeoIP
X-User
X-Skip-Cache
Locid
X-TEC-API-ROOT
X-TEC-API-ORIGIN
X-TEC-API-VERSION
Webserver
X-Varnish-CookieINHashed-On
X-Varnish-CookieHashed-On
X-Via-NSCOPI
X-Cache-Id
X-Gzip
X-Planisys-CDN-Rules
X-HS-Content-Campaign-Id
X-Varnish-Remaining-TTL
X-CACHE-KEY
X-DefHash
X-Unique-Id
X-Planisys-CDN-Cache
CPC-Cache
CPC-Age
VNS-Age
X-DefElseHash
X-Planisys-CDN-TTL
Cache-Hits
X-Esi-Check
My-App
VNS-Cache
Powered-By-ChinaCache
X-Ftr-Request-Id
X-Zone
X-Mvc-Supplant-OutputCached
X-Refresh
XServer
X-Vc
X-Conf
X-TX-ID
X-GEO
MIME-Version
X-Via-Popv
X-BBC-Edge-Cache-Status
X-PJAX-URL
X-Via-Popn
X-Cache-Ttl
X-Via-Poph
X-Pass-Why
X-TIME
X-Worker
X-NC
X-Internal-Host
Geo-Info
X-ID
X-OVcl-Cache
X-OVcl
X-Servedbyhost
X-Auto-Login
Time
X-Ckpd-Fst-Backend
Memory
WebServer
X-TraceId
X-V-Cache
X-LB-ID
X-NCache
Cf-Bgj
X-Ratelimit-Remaining
X-LSADC-Cache
X-Backend-TTL
X-DC
X-Render-Time
Magicmarker
Server-ID
X-Rocket-Nginx-Serving-Static
X-Webkit-Csp
DB-Nickname
X-NewRelic-App-Data
X-ZONE
X-Tx-Id
X-M-Log
X-Qnm-Cache
X-M-Reqid
Geoip-Latitude
X-Traceid
X-Cache-Remote
GeoIp-Country-Code
X-Geo
X-Newrelic-Synthetics
X-Platform-Processor
HostName
X-SD-PageType
X-Dispatcher-Server
X-App
X-Wa
X-Platform-Router
X-Platform-Cluster
Hostname
X-Method
Environment
X-CLOUD-TRACE-CONTEXT
X-Origin-Time
X-Gdpr
X-BBC-Origin-Response-Status
X-Cache-Config
X-Nyt-Route
X-IP
Resin-Trace
X-Datadog-Parent-Id
X-Datadog-Sampling-Priority
Ssr
X-Datadog-Trace-Id
X-API-Version
X-Tb-Optimization-Total-Bytes-Saved
X-Correlation-ID
X-Edge-Pop
X-Server-IP
X-NodeID
X-Via-Ucdn
X-VCL-Version
X-Pod-Name
Cluster
LB
X-Li-Proto
Ohc-File-Size
Tcn
X-Webkit-CSP-Report-Only
X-HITS
X-MSEdge-Features
X-Dynatrace
X-MSEdge-Flight
X-CACHE-AGE
X-Origin-Response-Time
Candidate-Md5Url
X-Cache-Var-Map
X-Cache-Var
X-Varnish-Beresp-TTL
X-ElasticPress-Query
X-LI-Proto
X-Trv-Group
X-Nc
Cf-Ipcountry
X-DynaTrace-JS-Agent
N-Cache
X-Via-CDN
Web-Mar-Region
X-Node-Id
X-Vcl-Version
X-Akamai-Pragma-Client-IP
Datacenter
X-Wix-Viewer-Type
X-APP
X-ND-Cache
Env
X-ServerName
X-HostName
X-Cs
X-Reqid
Proxy-Connection
X-Fastly-Request-Id
Onion-Location
GeoIP-Country-Code
GeoIP-Latitude
X-HS-Status
CDN
Server-Id
Sid
X-WA
CF-Cached-On
X-Ua-Browser
Rt-Fastcgi-Cache
Viewtype
Cdn
X-AB
X-Dynatrace-Js-Agent
X-Content
VivaBuild
WWW-Authenticate
X-Varnish-Cacheable
Servername
X-MG-S
X-NGINX-Cache
WZWS-RAY
X-Fastly-Backend-Reqs
X-FTR-Request-ID
X-EIG-Tracking-Id
Machine
X-CSRF-TOKEN
X-URL
X-Cdn-Forward
X-Lb-Id
X-Check-Cacheable
X-Esi
Ohc-Cache-HIT
X-Xrds-Location
Redirect-Candidate
X-Request-Start
X-IN-APIGATEWAYSSL
X-Fpc
X-VC
Cteonnt-Length
X-Via-PopV
X-Via-PopN
X-Via-PopH
X-IN-APIGATEWAY
On-Server
X-TIM-N
X-ServedByHost
X-Cache-Backend
X-Tid
Server-Ttl
FSS-Cache
X-Pjax-Url
X-ECache
Mime-Version
CountryCode
Shield-Pop
X-SN
URI
X-Swa-Ws
X-Tt-Logid
X-Contensis-Viewer-Groups
X-Varnish-Authentication
X-Oss-Request-Id
CACHE
Lb
X-Pad
X-Oss-Storage-Class
X-Oss-Server-Time
X-Oss-Object-Type
X-Cache-ASPX
X-Oss-Hash-Crc64ecma
X-Air-Pt
X-Amz-Meta-Cb-Modifiedtime
X-Cache-Date
X-FTR-Backend
X-FTR-Realm
X-Up
Pramga
X-Swift-Error
X-FORWARDED-FOR
Tracecode
X-Country-Code-Real
X-FTR-Backend-Server
X-FTR-Cache-Status
X-FTR-Balancer
X-FTR-DC
Xc-Version
X-DI
X-Acquia-Application-UUID
X-Acquia-Site
X-RPS
X-DSS
X-Acquia-Purge-Tags
X-DB
X-RPM
X-Sn-Servicetimems
X-Acquia-Application-Trace
X-StackifyID
X-RSL
Xet-Cookie
X-Cdn-Origin
Is-Us
X-DW
X-Dw-Trace-Id
X-Pf-Uncompressing
Warning
X-ElasticPress-Search
X-Yottaa-OS
X-Action
X-SB
X-LiteSpeed-Cache-Control
Ohc-Response-Time
Vha6-Origin
X-Webstats-RespID
X-Fastly-Cache-Hits
WP-Super-Cache
X-CCM
X-B3-Spanid
CloudFront-Viewer-Country
X-Mg-Request-Id
X-Hcs-Proxy-Type
X-Core-Mission
X-RAMCache
X-FPC
Content-Style-Type
Content-Script-Type
X-Snapshot-Date
X-TH-Server
X-MiniProfiler-Ids
ServerName
X-FTR-Expires
X-C
X-CCDN-Origin-Time
X-CCDN-CacheTTL
X-CUA